Who you’re working with

Clinton Wanner

I review the AI systems companies are shipping. Twelve-plus years in security, from penetration testing through security architecture. I have led teams since 2020, and I build tool-calling agents myself, so the review is grounded in implementation—not just policy. Wanner Labs is where I do that work directly for you.

Portrait of Clinton Wanner
Clinton Wanner · Plano, Texas

The day job, and why it matters to you

The advice you get here comes from running this work in production at a fintech, not from a framework binder.

I’m currently Director of Security Architecture and Application Security at a fintech digital-banking company, where I’ve led both teams since July 2024. In that role I’m a trusted advisor to CISO- and C-level stakeholders and to the 350+ financial institutions the company serves, environments where PCI DSS, NIST CSF 2.0, and Cloud Security Alliance expectations are the floor, not the ceiling.

I also build the systems I review. I architect autonomous LLM and tool-calling agents for ticket auditing, risk escalation, and executive reporting. I also run self-hosted agents in isolated MicroVM environments for code analysis and remediation. That is why the review is technical rather than a questionnaire: I have had to scope an agent’s permissions, decide what it may touch on its own, and live with the answer.

Underneath that is a decade of the fundamentals the AI layer still rests on. I’ve built cloud security programs from scratch, including posture management, AWS IAM at scale, and automated remediation. I practice DevSecOps with SAST and SCA wired into CI/CD. Zero trust work since 2019, including least-privilege IAM scoped from real audit-log usage rather than guesswork. Agent permissions are the same problem with a faster-moving caller.

One boundary, stated up front: because my employer is in financial services, I don’t take work with banks, credit unions, payments companies, or anyone selling primarily into that market. If that’s you, I’ll say so on our first call and point you to someone good.

I keep the practice direct: I do the technical work myself, I say what I actually think, and engagements end with written decisions your team can act on.

On the record

The verifiable parts, in one place.

Certifications
CISSP · OSCP · AWS Solutions Architect – Associate (Alumni) · Databricks GenAI Fundamentals
Compliance domains
PCI DSS · NIST CSF 2.0 · Cloud Security Alliance
Education
M.S. Information Technology and Management, University of Texas at Dallas (2014–2017)
Published
“Ransomware is on the rise,” Western Bankers Magazine
Leadership
6 years with direct reports; currently leading dual teams (Security Architecture + Application Security)
Based in
Plano, Texas

Tell me what you’re building

A few sentences is plenty. I read every message and reply myself. No sales handoff. You’ll speak directly with the person doing the work.